President Donald Trump signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.

President Donald Trump signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.

      President Donald Trump has issued a National Security Presidential Memorandum that allows US federal law enforcement to execute offensive cyber operations against transnational criminal organizations operating overseas. Essentially, Washington is formally permitting itself to hack the hackers, and this carries significant implications.

      The memorandum targets foreign criminal entities that negatively affect Americans through ransomware, phishing, financial fraud, sextortion, and a surge of AI-driven impersonation scams witnessed over the past year. The goal is to disrupt these operations at their origin rather than waiting for the repercussions to impact the US.

      The statistics related to this order are quite alarming. The White House reports that cybercrime losses are projected to reach $20.8 billion in 2025, with 73% of US adults having faced online scams. Even more concerning, one in seven young individuals victimized by sextortion has admitted to self-harm, highlighting that the human toll of these networks cannot be quantified solely in financial terms.

      The program is structured with proper oversight. A new National Coordination Center, which will function under a Homeland Security Task Force and be jointly led by the Department of Justice and the Department of Homeland Security, will manage operations. The Homeland Security Council is responsible for establishing protocols, and the memorandum requires “rigorous procedures” for review and adherence to the Constitution, US laws, and international treaties.

      A particularly notable aspect involves the private sector. The coordination center is instructed to “leverage the capability and innovation of the private sector” to conduct operations under government supervision and control. This means that private companies could potentially be involved in breaking into criminal networks abroad, a threshold many governments have historically been cautious about crossing.

      This raises concern for European audiences. State-sanctioned offensive hacking, even against clearly harmful targets, is a capability that could be hard to turn off once activated. A major concern is escalation; criminal groups frequently share infrastructure with legitimate businesses, and attacking one may inadvertently impact the other.

      Attribution presents another challenge. Cyber operations are notoriously difficult to track, which is part of what makes them appealing to criminals; that same uncertainty applies when a government conducts operations. A failed attempt or an operation targeting the wrong server in an unintended country may not be easily reversed or convincingly denied.

      There’s also the issue of collateral damage. Those managing these criminal enterprises are adept at concealing themselves among regular users. Thus, an operation targeting a scam network or ransomware group risks unintentionally affecting innocent bystanders, foreign companies, or even allied infrastructure, as evidenced by various botnet takedown attempts.

      The involvement of private contractors complicates matters further. Giving offensive tools to commercial firms, despite the memo's assurances of “direction and control,” blurs the distinction between public accountability and private interest. Europe has spent considerable time attempting to regulate the commercial spyware industry for this reason, and Washington’s decision to involve contractors in government cyber offensives is likely to attract scrutiny in Brussels.

      Admittedly, the threat is genuine, and the current measures are evidently ineffective. Ransomware gangs and scam networks have prospered due to the disparity between their operational locations and their victims’ homes, with traditional law enforcement, constrained by borders, struggling against deepfake-driven fraud and the fraud economy.

      The critical question is whether safeguards can be maintained. While “rigorous procedures” and constitutional compliance sound comforting in a fact sheet, the real test will arise the first time an operation fails, when a contractor exceeds their bounds, or when an allied government queries who authorized the code running on a server within its jurisdiction.

Other articles

Brazil instructs Discord to halt livestreaming following the death of a 13-year-old. Brazil instructs Discord to halt livestreaming following the death of a 13-year-old. Brazil's data protection agency has instructed Discord to halt its Go Live feature within three days following the death of a teenager, examining the extent to which a government can exert pressure on a platform regarding child safety. Anthropic is reportedly negotiating to acquire Decart for $6 billion, marking its largest transaction to date. Anthropic is reportedly negotiating to acquire Decart for $6 billion, marking its largest transaction to date. Anthropic is said to be negotiating the acquisition of Israeli startup Decart for approximately $6 billion, marking its largest transaction to date. This move reflects a focus on efficiency over scale as the company prepares for an IPO. Meta reports that it has deleted 756,000 accounts belonging to Australian teenagers, yet the majority of users under 16 still remain active online. Meta reports that it has deleted 756,000 accounts belonging to Australian teenagers, yet the majority of users under 16 still remain active online. Meta reports that it has disabled 756,000 accounts belonging to Australians under the age of 16, but research indicates that over 80% of teenagers are still finding ways to bypass the social media prohibition in the country. All the announcements from Made by Google 2026: Pixel 11 series, Pixel Watch 5, and Pixel Tag. All the announcements from Made by Google 2026: Pixel 11 series, Pixel Watch 5, and Pixel Tag. Google revealed a lot today: four new smartphones, a revamped smartwatch, its first-ever tracker, and a host of Gemini features. Anthropic is reportedly negotiating to acquire Decart for $6 billion, marking its largest deal to date. Anthropic is reportedly negotiating to acquire Decart for $6 billion, marking its largest deal to date. Anthropic is said to be negotiating to acquire Israeli startup Decart for approximately $6 billion, marking its largest acquisition to date. This move focuses on enhancing efficiency rather than expanding scale as the company prepares for an IPO. Meta reports that it has deleted 756,000 accounts belonging to Australian teenagers, yet the majority of users under 16 remain active online. Meta reports that it has deleted 756,000 accounts belonging to Australian teenagers, yet the majority of users under 16 remain active online. Meta reports that it has disabled 756,000 accounts in Australia belonging to users under the age of 16; however, research indicates that over 80% of teenagers are still finding ways to circumvent the nation's social media restrictions.

President Donald Trump signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.

A recent presidential memorandum permits US law enforcement to conduct offensive cyber operations targeting foreign criminal organizations, as well as to engage private contractors for assistance.